api.telegram.org
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:39
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 149.154.166.110
- Nameservers
- -
- Status
- -
Observed in malware
About SMS Forwarder (provisional)
A broad class of simple **Android OTP/SMS stealers** (packages like `com.example.smsforwarder`) that register a `RECEIVE_SMS` receiver and exfiltrate every incoming message - one-time passwords above all - to the operator. Two exfil channels are seen in the wild and both are recovered binary-only: - **Telegram bot** - the message is sent through the Telegram Bot API; the bot token(s) (`<id>:<authstring>`) and target `chat_id` are hardcoded, so `api.telegram.org` is the C2 and the **bot token is the actionable IOC** (report the bot, block the channel). A single build often carries more than one bot token (primary + fallback). - **HTTP drop** - the message is POSTed to a hardcoded endpoint, typically a bare IP with an `/sms` / `ingest` PHP handler. Family label is provisional - these are commodity builders, not a single actor.
About Telegram Bot RAT (provisional)
**Telegram Bot RAT (provisional)** is a heavily obfuscated Android RAT that uses a Telegram bot as its entire command-and-control channel. The operator drives the device over Telegram with a rich command set (/shell, /sendsms, /getsms, /getcontacts, /getcalllogs, /getlocation, /cam, /backcam, /microphone, /inflate overlay injection, /hideicon, /uninstall and more) implemented across an Accessibility, overlay and SMS service stack (CallBotService, MyAccessibilityService, NotificationListener, HeadlessSmsSendService). All strings, including the C2 (https://api.telegram.org/bot<token>/) and the operator chat_id, are hidden behind a reused obfuscator where plaintext = XOR(base64-decode(s), key "UTF-8"). Package, class and service names are randomised per build. Tracked samples form a single-operator campaign around Telegram bot ID 8737455264 (two rotated token secrets) beaconing to chat_id 7687499928, repackaged under many lures (fake system updates, Chrome, Viber, Google services, games). Family label provisional.
About Telegram Bot Stealer (provisional)
Android data stealer that exfiltrates to an attacker-run Telegram bot via the Telegram Bot API (api.telegram.org). Seen disguised as a "Free TikTok" app, it ships its bot token, destination chat_id and a decoy redirect as plaintext assets and uses the full Telegram Bot API set (sendMessage/sendDocument/…) to ship stolen SMS and device data to the operator's chat. Family label provisional.
About Telegram Dropper (provisional)
Android banking-malware dropper that leans on commodity cloud services for delivery and control. It pulls second-stage configuration/payloads and exfiltrates data through the Telegram Bot API (api.telegram.org) and t.me channels, with Firebase (Realtime Database / Storage) and DuckDNS hosts (e.g. binarypanel.duckdns.org) used as fallback C2/staging. Family label provisional.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.